PT-2026-91592 · Apple · Visionos+7
CVE-2026-84530
·
Published
2026-05-19
·
Updated
2026-09-22
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 26.7
iPadOS versions prior to 26.7
macOS Golden Gate versions prior to 27
macOS Tahoe versions prior to 26.7
tvOS versions prior to 27
visionOS versions prior to 27
watchOS versions prior to 27
Description
An information disclosure issue exists where an application can disclose kernel memory. Specifically, a kernel address leak occurs in the AIO (Asynchronous I/O) subsystem. The
aio register kevent function places an aio workq entry pointer into kqueue metadata. This pointer is subsequently copied into kn sdata by kevent register and stored in kn hook by filt aioattach, but it is never cleared from kn sdata. Consequently, userspace can read this leftover kernel pointer via kqext sdata.Recommendations
Update iOS to version 26.7 or later.
Update iPadOS to version 26.7 or later.
Update macOS Golden Gate to version 27 or later.
Update macOS Tahoe to version 26.7 or later.
Update tvOS to version 27 or later.
Update visionOS to version 27 or later.
Update watchOS to version 27 or later.
Fix
DoS
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Ios
Ipados
Macos Golden Gate
Macos Tahoe
Tvos
Visionos
Watchos